<email address hidden> weakness , remote attackers to execute arbitrary
Bug #1736244 reported by
Carl
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Bazaar |
New
|
Undecided
|
Unassigned |
Bug Description
bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-16228, CVE-2017-1000116, and CVE-2017-1000117.
U.S. Department of Homeland Security US-CERT
National Cyber Awareness System:
SB17-338: Vulnerability Summary for the Week of November 27, 2017
https:/
information type: | Private Security → Public Security |
To post a comment you must log in.